PT-2022-6286 · Linux+1 · Linux Kernel+1

Mauro Matteo Cascella

·

Published

2022-09-01

·

Updated

2024-06-15

·

CVE-2022-2308

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel with VDUSE backend (affected versions not specified)
Description A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse vdpa get config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00743
CVE-2022-2308
MGASA-2022-0379
MGASA-2022-0380
OPENSUSE-SU-2024:12320-1
OPENSUSE-SU-2024:13704-1

Affected Products

Astra Linux
Linux Kernel